LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-41461

CVE-2026-41461 - Vulnerability Analysis

HighCVSS: 8.5

Last Updated: April 23, 2026

SocialEngine - Server-Side Request Forgery

Published: April 23, 2026Updated: April 23, 2026Remote Exploitable

Overview

SocialEngine <= 7.8.0 contains a server-side request forgery caused by unsanitized user input in the /core/link/preview endpoint's uri parameter, letting authenticated attackers make arbitrary HTTP requests, exploit requires authentication.

Severity & Score

Severity: High
CVSS Score: 8.5

Impact

Authenticated attackers can make the server send arbitrary HTTP requests, enabling internal network enumeration and access to restricted services.

Mitigation

Update to the latest version beyond 7.8.0.

Details

CVE ID
CVE-2026-41461
Severity
High
CVSS Score
8.5
Type
server_side_request_forgery
Status
new

CWE

  • CWE-918

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N